We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Threats

Threats

Your Vendor Got Hacked: What a Third-Party Data Breach Means for You, and the One-Hour Vendor Review

A third-party data breach lands on your desk even when the hack was not yours. Which vendors matter, what to ask them, and a review that takes one hour.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The clearinghouse is on the evening news, and nobody called

The office manager of a three-location physical therapy group hears about it from her sister, who saw a headline on her phone. The billing clearinghouse that moves the group's claims to insurers has been breached. Patient names, dates of birth, insurance IDs and diagnosis codes, going back years, possibly.

She checks her inbox. Nothing from the vendor. She checks the vendor's website. A banner says they are "aware of a security incident" and "working with leading experts." She calls the account rep, who is out of office until Monday.

The practice owner asks the obvious question: "Which of our patients are affected?" She cannot answer. Then he asks the harder one: "Who else has our patient data?" She starts a list on a legal pad. The clearinghouse. The EHR company. The appointment-reminder texting service. The transcription vendor the new physical therapist uses. The payroll company, for staff. The IT firm that has admin access to everything. The cloud fax service. The marketing agency that once got a patient list for a mailer.

By the end of the hour the list has fourteen names, and she has a signed business associate agreement for six of them. She has never asked any of the fourteen a single question about their security. She has been told, in effect, that a stranger's password hygiene now determines whether her practice sends breach letters to 9,000 patients.

What the heck does this mean

A third-party data breach is a breach at a company you do business with that exposes your data or your customers' data. You did nothing wrong, technically. You still get the phone calls.

A supply chain cyber attack is the same idea seen from the attacker's side: hit one vendor, reach every customer of that vendor. Breaking into 400 physical therapy practices is hard. Breaking into the one clearinghouse they all use is a much better return on effort.

Vendor risk is the exposure you inherit from everyone who holds your data or has access to your systems. It includes the IT firm with the admin password and the intern's favorite file-sharing tool.

A guest account is a login your vendor's staff or a former contractor holds in your cloud tenant. Most businesses have dozens they have forgotten about, still active, still able to open the shared drive.

Here is the reframing that matters: your security perimeter is not your office. It is the sum of every company that can log in to your systems or hold your files, and most owners have never written that list down.

The numbers that matter

35.5% of publicly reported breaches in 2024 were third-party related, according to the SecurityScorecard 2025 Global Third-Party Breach Report. More than a third of the breach letters that went out that year came from a vendor's mistake, not the sender's.

98% of organizations have a relationship with a vendor that has been breached, in the same SecurityScorecard 2025 report. Read that as a certainty, not a risk. One of yours already has.

69% of monitored SaaS accounts in small and midsize business tenants were unmanaged guest accounts, per the Kaseya 2026 SaaS Security Report. Two out of three logins in the average small-business cloud belong to somebody nobody is watching.

What to do this week

  1. Write the vendor list. One hour, one spreadsheet: vendor name, what data they hold, whether they have a login to your systems, and who at your company owns the relationship. Fourteen names on a legal pad is a good start. (CIS 15 Service Provider Management)
  2. Mark the five vendors that could hurt you most if they were breached tomorrow, and send each one the five questions in the FAQ below. Give them two weeks. (CIS 15 Service Provider Management)
  3. Pull the guest and external accounts from your cloud tenant and disable every one nobody can name. Do the same for the IT firm's admin accounts: are they named individuals, and do they have MFA? (CIS 5 Account Management)
  4. Find out which vendors have full copies of your data and whether they need them. The marketing agency did not need every patient's date of birth for a postcard. Send less. (CIS 3 Data Protection)
  5. Add a vendor breach to your incident plan: who calls the vendor, who determines which customers are affected, and where the contract's notification clause lives. (CIS 17 Incident Response Management)
  6. Put a security clause and a breach-notification deadline in your standard vendor contract template, so the next agreement you sign has them without a fight. (CIS 15 Service Provider Management)

Where AccuSights fits

Our assessment builds the vendor list with you, ranks it by what each vendor could cost you, then checks the part you can see: guest accounts, admin logins, data copies nobody needed. The Cyber Hygiene Test takes three minutes and gives a starting score. If the vendor question keeps you up, 15 minutes with an engineer turns the legal pad into a plan.

Questions people ask

What questions should I ask a vendor about security? Five will do for a first pass. What data of ours do you hold and where is it stored? Do you require multi-factor authentication for your own staff and for our users? When did you last have an independent security assessment, and can we see the summary? How will you tell us about a breach, and how fast? Who else do you share our data with? A vendor that cannot answer in a week has told you something.

Am I liable if my vendor loses my customers' data? In most cases, yes, at least in part. Your customers gave their data to you, not to your billing company, and the notification duty and the reputational bill usually come to your door first. Your contract may let you recover costs from the vendor afterward, but only if you negotiated for it. Read the limitation of liability clause in your biggest vendor contract this week.

What is a business associate agreement? It is the contract US healthcare providers must sign with any vendor that handles patient information on their behalf, under HIPAA. It spells out what the vendor may do with the data, what safeguards it must keep, and how it must report a breach to you. Signing one does not transfer your responsibility; it documents how the two of you will share it. If a vendor touches patient data and there is no agreement on file, fix that first.

You cannot control your vendor's security. You can control how much of your business you hand them, and whether you would find out first.

Questions people ask

What questions should I ask a vendor about security?

Five will do for a first pass. What data of ours do you hold and where is it stored? Do you require multi-factor authentication for your own staff and for our users? When did you last have an independent security assessment, and can we see the summary? How will you tell us about a breach, and how fast? Who else do you share our data with? A vendor that cannot answer in a week has told you something.

Am I liable if my vendor loses my customers' data?

In most cases, yes, at least in part. Your customers gave their data to you, not to your billing company, and the notification duty and the reputational bill usually come to your door first. Your contract may let you recover costs from the vendor afterward, but only if you negotiated for it. Read the limitation of liability clause in your biggest vendor contract this week.

What is a business associate agreement?

It is the contract US healthcare providers must sign with any vendor that handles patient information on their behalf, under HIPAA. It spells out what the vendor may do with the data, what safeguards it must keep, and how it must report a breach to you. Signing one does not transfer your responsibility; it documents how the two of you will share it. If a vendor touches patient data and there is no agreement on file, fix that first.

Controls this post maps to

CIS 15 Service Provider ManagementCIS 3 Data ProtectionCIS 17 Incident Response Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.